{"containers":{"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2006-04-21T00:00:00.000Z","descriptions":[{"lang":"en","value":"PHP remote file inclusion vulnerability in dForum 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DFORUM_PATH parameter to (1) about.php, (2) admin.php, (3) anmelden.php, (4) losethread.php, (5) config.php, (6) delpost.php, (7) delthread.php, (8) dfcode.php, (9) download.php, (10) editanoc.php, (11) forum.php, (12) login.php, (13) makethread.php, (14) menu.php, (15) newthread.php, (16) openthread.php, (17) overview.php, (18) post.php, (19) suchen.php, (20) user.php, (21) userconfig.php, (22) userinfo.php, and (23) verwalten.php."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-19T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"ADV-2006-1482","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2006/1482"},{"name":"20060421 dForum <= 1.5 Multiple Remote File Inclusion Vulnerabilities.","tags":["mailing-list","x_refsource_BUGTRAQ"],"url":"http://www.securityfocus.com/archive/1/431758"},{"name":"19788","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/19788"},{"name":"20060421 dForum <= 1.5 Multiple Remote File Inclusion Vulnerabilities.","tags":["mailing-list","x_refsource_FULLDISC"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045369.html"},{"name":"dforum-dforumpath-parameter-file-include(26035)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26035"},{"tags":["x_refsource_MISC"],"url":"http://www.nukedx.com/?viewdoc=27"},{"name":"17650","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/17650"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2006-1994","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"PHP remote file inclusion vulnerability in dForum 1.5 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the DFORUM_PATH parameter to (1) about.php, (2) admin.php, (3) anmelden.php, (4) losethread.php, (5) config.php, (6) delpost.php, (7) delthread.php, (8) dfcode.php, (9) download.php, (10) editanoc.php, (11) forum.php, (12) login.php, (13) makethread.php, (14) menu.php, (15) newthread.php, (16) openthread.php, (17) overview.php, (18) post.php, (19) suchen.php, (20) user.php, (21) userconfig.php, (22) userinfo.php, and (23) verwalten.php."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"ADV-2006-1482","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2006/1482"},{"name":"20060421 dForum <= 1.5 Multiple Remote File Inclusion Vulnerabilities.","refsource":"BUGTRAQ","url":"http://www.securityfocus.com/archive/1/431758"},{"name":"19788","refsource":"SECUNIA","url":"http://secunia.com/advisories/19788"},{"name":"20060421 dForum <= 1.5 Multiple Remote File Inclusion Vulnerabilities.","refsource":"FULLDISC","url":"http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045369.html"},{"name":"dforum-dforumpath-parameter-file-include(26035)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26035"},{"name":"http://www.nukedx.com/?viewdoc=27","refsource":"MISC","url":"http://www.nukedx.com/?viewdoc=27"},{"name":"17650","refsource":"BID","url":"http://www.securityfocus.com/bid/17650"}]}}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-07T17:35:31.075Z"},"title":"CVE Program Container","references":[{"name":"ADV-2006-1482","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2006/1482"},{"name":"20060421 dForum <= 1.5 Multiple Remote File Inclusion Vulnerabilities.","tags":["mailing-list","x_refsource_BUGTRAQ","x_transferred"],"url":"http://www.securityfocus.com/archive/1/431758"},{"name":"19788","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/19788"},{"name":"20060421 dForum <= 1.5 Multiple Remote File Inclusion Vulnerabilities.","tags":["mailing-list","x_refsource_FULLDISC","x_transferred"],"url":"http://lists.grok.org.uk/pipermail/full-disclosure/2006-April/045369.html"},{"name":"dforum-dforumpath-parameter-file-include(26035)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/26035"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.nukedx.com/?viewdoc=27"},{"name":"17650","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/17650"}]}]},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2006-1994","datePublished":"2006-04-25T10:00:00.000Z","dateReserved":"2006-04-25T00:00:00.000Z","dateUpdated":"2024-08-07T17:35:31.075Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"}